Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3p4-rxvp-pgmv

Опубликовано: 30 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

EPSS

Процентиль: 16%
0.00052
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-446

Связанные уязвимости

CVSS3: 5.9
nvd
около 1 месяца назад

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

EPSS

Процентиль: 16%
0.00052
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-446